BlueWallet / LndHub

Wrapper for Lightning Network Daemon. It provides separate accounts for end-users
http://LndHub.io
MIT License
745 stars 181 forks source link

[Snyk] Upgrade @grpc/proto-loader from 0.6.5 to 0.6.13 #463

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade @grpc/proto-loader from 0.6.5 to 0.6.13.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-PROTOBUFJS-2441248
517/1000
Why? Proof of Concept exploit, CVSS 8.2
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @grpc/proto-loader
  • 0.6.13 - 2022-06-06
    • bump protobufjs dependency to "^6.11.3" (#2131 contributed by @ ocofaigh)
  • 0.6.12 - 2022-05-05
    • Revert long dependency to 4.x (#2114)
  • 0.6.11 - 2022-05-03
    • Broaden dependency on long to 4.x or 5.x (#2112)
  • 0.6.10 - 2022-05-02
    • Update the dependency on the long library to version 5 to fix some TypeScript type compatibility issues (#2110)
  • 0.6.9 - 2022-01-05
  • 0.6.8 - 2022-01-04
  • 0.6.7 - 2021-11-16
  • 0.6.6 - 2021-10-18
  • 0.6.5 - 2021-09-13
from @grpc/proto-loader GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs

socket-security[bot] commented 2 years ago

Socket Security Report

πŸ“œ New install scripts detected

A dependency change in this PR is introducing new install scripts to your install step.

Package Script field Location
protobufjs@6.11.3 (upgraded) postinstall package.json via @grpc/proto-loader@0.6.13
Socket.dev scan summary
Issue Status
Did you mean? βœ… no new possible package typos
Install scripts ⚠️ 1 new install script detected
Telemetry βœ… no new telemetry
Troll package βœ… no new troll packages
Malware βœ… no new malware
Native code βœ… no new native modules

Powered by socket.dev